Sub-scope 09 (mongo) - execution probe: what the profile's TLS and timeout policy reaches
revision=a24ece9cf797f7ea647e33bf846b115208ed1ba5
generatedAt=2026-08-30T00:24:04+00:00

One temporary probe class was added, run, and removed:
  src/test/.../security/Ss09TlsProbe.java  (@Tag mongodb-contract, hermetic)
No production source was modified.

PROBE profile.tlsRequired=true -> validator ACCEPTED
PROBE settings Boot builds from the README's URI (spring.data.mongodb.uri, line 37):
        sslEnabled=false
        connectTimeoutMs=10000
        serverSelectionTimeoutMs=30000
        poolMaxSize=100
        serverApi=null
        uuidRepresentation=UNSPECIFIED
PROBE settings MongoClientSettingsFactory would build: sslEnabled=true

Reading: MongoSecurityProfileValidator accepts a production profile that declares TLS
required, and nothing applies that declaration to the driver, because
MongoClientSettingsFactory has no caller anywhere in the repository (8.1b, 8.1e).
The connect timeout, server-selection timeout, pool bounds, Stable API declaration and
pinned UUID representation the profile states are equally unapplied; the values above are
the driver's own defaults.

Contrast (8.1c): the identical defect on the observability half - a settings-builder
method with no caller - was fixed by registering a MongoClientSettingsBuilderCustomizer
in MongoDriverObservabilityAutoConfiguration. The same mechanism is available here and is
not used.

Note (8.1b): MongoTlsLaneTest proves the SERVER enforces TLS. It builds its own settings
with applyToSslSettings(ssl -> ssl.enabled(true)) by hand (line 137), so it does not
exercise the path from a profile's tlsRequired flag to a TLS connection.
$ git status --short | wc -l
0
exit=0

$ git status --short
exit=0

